Aggregator
From User Identity to Payroll Accuracy: Automating Local Tax Compliance with SaaS Tools
Learn how SaaS platforms can automate local payroll tax compliance using identity data, real-time tax APIs, geolocation, and secure workflows for accuracy.
The post From User Identity to Payroll Accuracy: Automating Local Tax Compliance with SaaS Tools appeared first on Security Boulevard.
Real-estate finance services giant SitusAMC breach exposes client data
CVE-2017-9603 | WP Jobs Plugin up to 1.4 on WordPress wp-admin/edit.php jobid sql injection (EDB-42172)
CVE-2017-14845 | Mojoomla WPCHURCH Church Management System on WordPress ID sql injection (EDB-42800)
CVE-2017-14847 | Mojoomla WPAMS Apartment Management System on WordPress ID sql injection (EDB-42805)
CVE-2017-9834 | WatuPRO Plugin up to 5.5.3.6 on WordPress wp-admin/admin-ajax.php watupro_questions sql injection (EDB-42291)
CVE-2017-14843 | Mojoomla School Management System on WordPress ID sql injection (EDB-42804)
CVE-2017-16562 | UserPro Plugin up to 4.9.17.0 on WordPress up_auto_log access control (EDB-43117 / Nessus ID 110482)
CVE-2017-14126 | Participants Database Plugin up to 1.7.5.9 on WordPress cross site scripting (EDB-42618)
CVE-2025-55059 | Rumpus FTP Server 9.0.12 cross site scripting
CVE-2025-26391 | SolarWinds Observability Self-Hosted cross site scripting (EUVD-2025-197927 / WID-SEC-2025-2615)
CVE-2025-40545 | SolarWinds Observability Self-Hosted redirect (EUVD-2025-197926 / WID-SEC-2025-2615)
Shai-Hulud 2.0: over 14,000 secrets exposed
On November 24, a new wave of the Shai-Hulud supply chain attack emerged. The threat actors exfiltrate stolen credentials directly to GitHub repositories created with compromised tokens. GitGuardian identified 14,206 secrets across 487 organizations, with 2,485 still valid.
The post Shai-Hulud 2.0: over 14,000 secrets exposed appeared first on Security Boulevard.
[Control systems] CISA ICS security advisories (AV25-782)
CVE-2025-63433 | Xtooltech Xtool AnyScan App up to 4.40.40 on Android hard-coded key (EUVD-2025-198966)
CVE-2025-63432 | Xtooltech Xtool AnyScan Android Application up to 4.40.40 SSL certificate validation (EUVD-2025-198967)
А вы знали, что ваш VPN теперь видно? Илон Маск нашел способ показать всем, что вы врете о своем местоположении
Hackers Leveraging WhatsApp to Silently Install Malware to Harvest Logs and Contact Details
A new malware campaign targeting Brazilian users has emerged, using WhatsApp as its primary distribution channel to spread banking trojans and harvest sensitive information. This sophisticated attack leverages social engineering by exploiting the trust victims place in their existing contacts, making the malicious files appear legitimate. The campaign begins with phishing emails containing archived VBS […]
The post Hackers Leveraging WhatsApp to Silently Install Malware to Harvest Logs and Contact Details appeared first on Cyber Security News.